CVE-2026-3037

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by modifying malicious input injected into the MBird SMS service URL and/or code via the utility route which is later processed during system setup, leading to remote code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:copeland:xweb_300d_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:copeland:xweb_300d_pro:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:copeland:xweb_500d_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:copeland:xweb_500d_pro:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:copeland:xweb_500b_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:copeland:xweb_500b_pro:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-27 02:16

Updated : 2026-06-17 10:42


NVD link : CVE-2026-3037

Mitre link : CVE-2026-3037

CVE.ORG link : CVE-2026-3037


JSON object : View

Products Affected

copeland

  • xweb_500b_pro
  • xweb_500d_pro_firmware
  • xweb_500d_pro
  • xweb_300d_pro_firmware
  • xweb_300d_pro
  • xweb_500b_pro_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')